What to tell the auditor when they ask who wrote your training
There is a moment in every conversation about AI-generated training where someone senior asks a version of the same question. If the AI wrote it, who is accountable for what it says?
It is the right question, and most answers to it are bad. "A human reviewed it" is not an answer, because it describes an intention rather than a record. "The model is very accurate" is worse, because accuracy is not the issue: attribution is.
The question behind the question
An auditor asking who wrote your training is not conducting a philosophical inquiry into machine authorship. They are asking something narrower and much more answerable:
- What did the training say at the time the person completed it?
- What source material was it based on?
- Who was accountable for deciding it was correct?
- Can you show me the record rather than telling me about it?
None of those questions is about AI. They are the same questions an auditor would ask about a course written by a contractor in 2019. The reason AI makes people nervous is that the usual answers get vaguer, not that the questions change.
Why the usual answers get vaguer
When an instructional designer writes a course from a policy document, the provenance lives in their head and in a folder of drafts. That is thin, but it survives because there is a person to ask.
When a model drafts the course, that person is gone from the drafting step. If nothing replaced them, you now have content whose origin nobody can reconstruct. The chat history is not a substitute: it is not attached to the course, it is not versioned with it, and in eighteen months nobody will find it.
The failure is not that AI wrote the content. It is that the provenance was never captured in the artefact.
Capturing provenance in the artefact
The fix is unglamorous. Provenance has to be recorded per slide, in the course, at the moment of generation:
- Which document, and which page. Not "the privacy policy" but the document and the page range, with the excerpt the slide was written from.
- How confident the system was. A confidence score tells a reviewer where to look. Review that treats every slide equally is review that runs out of attention before it reaches the risky ones.
- Who approved it, and when. Per module, not per course, so that a section nobody read cannot ride along with the ones that were.
- What it said at the time. Versions, so the course as it stood during the period under review is still retrievable after it has been superseded.
With those four things, the answer to the auditor becomes a description of a record rather than a claim about a process.
The answer
An author defined the scope and approved the structure before any content was generated. The content was drafted from named source documents, and each slide records the document and page range it was derived from. A named reviewer approved each module, and the system holds a timestamped record of every generation, edit and approval. The version live during the period you are asking about is still available.
Notice what that answer does not do. It does not claim the AI is reliable. It does not ask the auditor to trust a vendor. It describes a chain of human decisions with a record attached to each one, which is exactly what an audit is looking for.
The uncomfortable part
This only works if the review is real. A gate that everyone clicks through is not governance, and a citation nobody checks is decoration.
The honest version of the pitch is that generative authoring moves the work rather than removing it. Drafting gets much cheaper. Verifying stays exactly as expensive as it always was, and the tooling can only make it easier to aim: showing the reviewer which slides the system was least sure about, and putting the source excerpt next to the claim so checking it takes seconds rather than minutes.
If your reviewers do not have the time to do that, generative authoring will produce unverified courses faster than you produced them before. That is a worse outcome than the backlog.
Where to start
Pick the course where the accountability question would be sharpest, not the easiest one. If a governed workflow cannot survive your most scrutinised course, it will not be worth much on the others. And if it can, you have answered the question that was going to come up eventually anyway.
Scheduled for review by 6 January 2027. We review anything that touches regulation on a cycle, because a confidently wrong post about compliance is worse than no post.
